Openmeetings

Vendor:

First CVE: Apr 11, 2016 · Active for 10 years

29
Total CVEs
More Total CVEs than 96% of tracked products
3.6
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 59% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Openmeetings over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 11, 2016
10 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

CVE Severity & Scoring

Openmeetings29 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network29 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (96.6%)
High1 (3.4%)
Unknown0 (0.0%)
User Interaction
None25 (86.2%)
Unknown0 (0.0%)
Required4 (13.8%)
Privileges Required
Low5 (17.2%)
High1 (3.4%)
None23 (79.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.
Sep 30, 20207.572NOYES
Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apache
Jan 8, 20259.867NONO
Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 allows remote authenticated administrators to write to arbit
Apr 11, 20166.556NOYES
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.
Jul 14, 20266.533NONO
Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0.
Jul 17, 201710.033NONO
Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms missing brute force protection.
Jul 17, 20179.831NONO
Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privileges in any room
Mar 28, 20239.830NONO
The (1) FileService.importFileByInternalUserId and (2) FileService.importFile SOAP API methods in Apache OpenMeetings before 3.1.1 improperly use the Java URL class without checkin
Apr 11, 20167.528NONO
The sendHashByUser function in Apache OpenMeetings before 3.1.1 generates predictable password reset tokens, which makes it easier for remote attackers to reset arbitrary user pass
Apr 11, 20167.528NONO
Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the structure of other queries bein
Jul 17, 20178.827NONO

Exploit Exposure

Signals from CVEs in this product scope (29 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
6.9% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (29 CVEs).

Media Mentions

Signals from CVEs in this product scope (29 CVEs).

Top CNAs Publishing CVEs For Openmeetings

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.2.1117.92.1%00
3.2.0117.92.1%00
3.1.598.12.1%00
3.1.498.12.1%00
3.1.398.12.1%00
3.1.298.12.1%00
3.1.198.12.1%00
3.1.098.12.1%00
3.0.787.82.0%00
3.0.687.82.0%00
3.0.587.82.0%00
3.0.487.82.0%00
3.0.387.82.0%00
3.0.287.82.0%00
3.0.187.82.0%00
3.0.087.82.0%00
2.2.087.82.0%00
2.1.187.82.0%00
2.187.82.0%00
2.087.82.0%00